Spring Boot 应用对接 Prometheus 监控指南

发布时间:2026/7/31 5:53:47
Spring Boot 应用对接 Prometheus 监控指南 Spring Boot 应用对接 Prometheus 监控指南本文档介绍如何将 Spring Boot 应用接入 Prometheus 监控体系分无认证和Basic Auth 认证两种情况说明。一、技术栈组件用途Micrometer指标采集门面Spring Boot Actuator暴露监控端点Prometheus指标采集 时序数据库Grafana指标可视化二、通用步骤两种场景都需要2.1 引入依赖!-- Spring Boot Actuator --dependencygroupIdorg.springframework.boot/groupIdartifactIdspring-boot-starter-actuator/artifactId/dependency!-- Prometheus Registry --dependencygroupIdio.micrometer/groupIdartifactIdmicrometer-registry-prometheus/artifactId/dependency2.2 配置 application.ymlserver:port:8086# 业务端口spring:application:name:janus-service1management:server:port:18086# 管理端口与应用端口隔离endpoints:web:exposure:include:health,info,prometheus# 暴露 Prometheus 端点endpoint:prometheus:enabled:true# 启用 Prometheus 端点metrics:tags:application:${spring.application.name}# 给指标打标签便于区分2.3 K8s Deployment 配置apiVersion:apps/v1kind:Deploymentmetadata:name:janus-service1namespace:gateway-defaultspec:template:metadata:annotations:# # 场景一无认证直接抓取# prometheus.io/scrape:trueprometheus.io/kind:janus-service1prometheus.io/port:18086prometheus.io/path:/actuator/prometheus# # 场景二Basic Auth 认证额外添加# # prometheus.io/auth: basic # ← 有认证时取消注释spec:containers:-name:janus-service1image:your-registry/janus-service1:latestports:-name:httpcontainerPort:8086protocol:TCP-name:managementcontainerPort:18086# 管理端口protocol:TCP三、场景一无认证内网/测试环境3.1 场景说明Prometheus 直接抓取/actuator/prometheus端点无需用户名密码验证适用于内网环境或测试环境3.2 配置清单配置项值说明prometheus.io/scrapetrue允许 Prometheus 抓取prometheus.io/port18086抓取端口prometheus.io/path/actuator/prometheus抓取路径prometheus.io/auth不配置无需认证3.3 验证命令# 1. Pod 内验证curlhttp://localhost:18086/actuator/prometheus|head-10# 2. 集群内验证curlhttp://pod-ip:18086/actuator/prometheus|head-10# 3. 查看 Prometheus Targetshttp://prometheus-host:9090/targets# 预期: State UP ✅四、场景二Basic Auth 认证生产环境4.1 场景说明Prometheus 抓取时需要携带 Basic Auth 凭证应用需要验证请求中的用户名密码适用于生产环境安全性更高4.2 新增依赖!-- 仅场景二需要 --dependencygroupIdorg.springframework.boot/groupIdartifactIdspring-boot-starter-security/artifactId/dependency4.3 配置 application.ymlspring:security:user:# ⚠️ 必须与 Prometheus 配置中的 basic_auth 一致name:usernamepassword:axxxxxxxxxxxxxxxxxxxxxxxmanagement:# ... 与场景一相同保持不变4.4 配置 Security只保护 /actuator 路径importorg.springframework.context.annotation.Bean;importorg.springframework.context.annotation.Configuration;importorg.springframework.core.annotation.Order;importorg.springframework.security.config.Customizer;importorg.springframework.security.config.annotation.web.builders.HttpSecurity;importorg.springframework.security.config.annotation.web.configuration.EnableWebSecurity;importorg.springframework.security.web.SecurityFilterChain;ConfigurationEnableWebSecuritypublicclassManagementSecurityConfig{/** * 只保护 /actuator/** 路径使用 Basic Auth */BeanOrder(1)publicSecurityFilterChainmanagementSecurityFilterChain(HttpSecurityhttp)throwsException{http.securityMatcher(/actuator/**).authorizeHttpRequests(auth-auth.anyRequest().authenticated()).httpBasic(Customizer.withDefaults()).csrf(csrf-csrf.disable());returnhttp.build();}/** * 其他所有请求放行不影响业务接口 */BeanOrder(2)publicSecurityFilterChaindefaultSecurityFilterChain(HttpSecurityhttp)throwsException{http.authorizeHttpRequests(auth-auth.anyRequest().permitAll()).csrf(csrf-csrf.disable());returnhttp.build();}}4.5 K8s 注解添加 auth 标记annotations:prometheus.io/scrape:trueprometheus.io/kind:janus-service1prometheus.io/port:18086prometheus.io/path:/actuator/prometheusprometheus.io/auth:basic# ← 告诉 Prometheus 需要认证4.6 Prometheus 配置运维侧scrape_configs:-job_name:janus-service1kubernetes_sd_configs:-role:podrelabel_configs:# 只抓取 scrapetrue 的 Pod-source_labels:[__meta_kubernetes_pod_annotation_prometheus_io_scrape]action:keepregex:true# 只抓取 authbasic 的 Pod-source_labels:[__meta_kubernetes_pod_annotation_prometheus_io_auth]action:keepregex:basic# 使用自定义路径-source_labels:[__meta_kubernetes_pod_annotation_prometheus_io_path]action:replacetarget_label:__metrics_path__# 使用自定义端口-source_labels:[__address__,__meta_kubernetes_pod_annotation_prometheus_io_port]action:replaceregex:([^:])(?::\d)?;(\d)replacement:$1:$2target_label:__address__# Basic Auth 认证配置basic_auth:username:usernamepassword:a48xxxxxxxxxxxxxxxxxxxxxxxxxx391